logo

TAMECAT PowerShell Backdoor Targets Edge and Chrome: Login Credentials At Risk

ID: 3a453b8a-c3d6-5586-b1bb-a07acbabf389

STIX ID: report--3a453b8a-c3d6-5586-b1bb-a07acbabf389

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-01-30

Date Updated: 2026-04-22

Author: Varshini

...
...

TAMECAT is a sophisticated PowerShell backdoor attributed to Iranian APT42 and observed in the SpearSpecter campaign; it uses a VBScript downloader and an AES-encrypted loader to deploy modular components that steal Edge and Chrome credentials via browser debugging, execute commands received from Telegram-based C2, and perform in-memory execution and exfiltration. The report provides IoCs (SHA256/SHA1/MD5 hashes, domains), C2 behavior, MITRE ATT&CK mappings, and mitigation recommendations including EDR/AV, PowerShell logging, and tighter browser security monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.